[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: OCSP response pre-production (was RE: POLL: Use of nonces in OCS P)




At 1:55 PM -0700 9/26/03, Deacon, Alex wrote:
Hi Russ,

Agreed, however we do not have control of all OCSP clients.  In the case
where a responder is using pre-produced responses and can't respond to a
request with a nonce, the responder can do one of two things:

1) Send the pre-produced response without the nonce
2) return a malformedReqest OCSPResponseStatus

That's not the correct status: "internalError" is much more appropriate. The request is *not* malformed: it is the responder that has an error (namely, that it cannot handle a valid request).


--Paul Hoffman, Director
--Internet Mail Consortium